VulnSea

themeatelier has 3 CVEs on record between 2025 and 2026. 1 was published in the last 90 days. The median CVSS is 8.6 (high). Most affected products: idonate (2), Domain For Sale (1).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
8.6
Publish → KEV
—
Last 90 days
1 prev 0

Weakness classes

Products

  • idonate 2
  • Domain For Sale 1
3
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

themeatelier vulnerabilities

CVEs affecting themeatelier, newest first. Open any entry for full detail, references, and exploit status.

3 CVEsRSS

CVE-2026-89023High· 8.6
3w ago

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources

ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its REST API endpoints that allows unauthenticated attackers to access and manipulate protected resources. Attackers can ret…

▾ TwilightThemeAtelier · Domain For SaleEPSS 0.39%via NVD
CVE-2025-4522Medium· 6.5
11mo ago

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function in versions 2.0.0 to 2.1.9

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Insecure Direct Object Reference via the admin_post_donor_delete() function in versions 2.0.0 to 2.1.9. By supplying an arbitrary use…

▾ Sunlitthemeatelier · idonateEPSS 0.25%via NVD
CVE-2025-4519High· 8.8
11mo ago

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_password() function in versions 2.1.5 to 2.1.9

The IDonate – Blood Donation, Request And Donor Management System plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the idonate_donor_password() function in versions 2.1.5 to 2.1.9. This make…

▾ Twilightthemeatelier · idonateEPSS 0.34%via NVD
themeatelier vulnerabilities (CVEs) · VulnSea